Practice Policies & Patient Information
Chaperones
This practice is committed to providing a safe and comfortable environment and to putting patients at ease wherever possible and strives to achieve good practice at all times.
All patients are entitled to have a chaperone present during any consultation, examination or procedure. Clinicians at this practice will advise patients that a chaperone is necessary during any intimate examination; this is to safeguard both the clinician and you, the patient.
Where a chaperone is not available, the clinician may ask you to remake the appointment and request the presence of a chaperone at the time of booking.
Staff members have received appropriate training to act as chaperones and have knowledge of the examination or procedure you may be undergoing.
Family and friends are not permitted to act as chaperones as they do not have the knowledge required, nor do they have the necessary training.
GDPR & Your Data
What is GDPR?
GDPR stands for General Data Protection Regulations and is a new piece of legislation that will supersede the Data Protection Act. It will not only apply to the UK and EU; it covers anywhere in the world in which data about EU citizens is processed.
The GDPR is similar to the Data Protection Act (DPA) 1998 (which the practice already complies with), but strengthens many of the DPA’s principles. The main changes are:
- Practices must comply with subject access requests
- Where we need your consent to process data, this consent must be freely given, specific, informed and unambiguous
- There are new, special protections for patient data
- The Information Commissioner’s Office must be notified within 72 hours of a data breach
- Higher fines for data breaches – up to 20 million euros
What is ‘patient data’
Patient data is information that relates to a single person, such as his/her diagnosis, name, age, earlier medical history etc.
What is consent?
Consent is permission from a patient – an individual’s consent is defined as “any freely given specific and informed indication of his wishes by which the data subject signifies his agreement to personal data relating to him being processed.”
The changes in GDPR mean that we must get explicit permission from patients when using their data. This is to protect your right to privacy, and we may ask you to provide consent to do certain things, like contact you or record certain information about you for your clinical records.
Individuals also have the right to withdraw their consent at any time.
Being transparent and providing accessible information to patients about how we will use your personal information is a key element of the GDPR Regulations.
The following notice reminds you of your rights in respect of the above legislation and how your GP Practice will use your information for lawful purposes in order to deliver your care and the effective management of the local NHS system.
This notice reflects how we use information for:
- The management of patient records;
- Communication concerning your clinical, social and supported care;
- Ensuring the quality of your care and the best clinical outcomes are achieved through clinical audit and retrospective review;
- Participation in health and social care research; and
- The management and clinical planning of services to ensure that appropriate care is in place.
Data Controller
As your registered GP practice, we are the data controller for any personal data that we hold about you.
Carnon Downs Surgery Privacy Notice, Leaflet & Quick Guide
Please click on the document below to see each version
Quick Guide
GP Net Earnings
NHS England requires that the net earnings of doctors engaged in practice is publicised, and the required disclosure is shown below. However, it should be noted that the prescribed method for calculating earnings is potentially misleading because it takes no account of how much time doctors spend working in practice and should not be used to form any judgement about GP earnings, nor to make any comparison with any other practice.
The average earnings for GPs working in Carnon Downs Surgery in the last financial year ending 31 March 2024 was £39,746 before tax and National Insurance.
This is for 0 full-time, 8 part-time GPs who worked in the practice for more than 6 months.
Named GP
Each patient is allocated a named doctor who is responsible for ensuring routine administrative tasks are kept up to date for you.
There is no obligation to see your named GP. If you would like to know who your named GP is please ask at Reception.
Privacy notice
What is a privacy notice?
The UK General Data Protection Regulation (GDPR) requires that data controllers provide certain information to people whose information (personal data) they hold and use. A privacy notice is one way of providing this information. This is sometimes referred to as a fair processing notice.
A privacy notice should identify who the data controller is, with contact details for its Data Protection Officer. It should also explain the purposes for which personal data are collected and used, how the data are used and disclosed, how long it is kept, and the controller’s legal basis for processing
Why do we need your data?
As your General Practice, we need to know your personal, sensitive and confidential data in order to provide you with appropriate healthcare services. Your records are used to facilitate the care you receive, and to ensure you receive the best possible healthcare. Information may be used within the GP practice for clinical audit, to monitor the quality of the service provided
What data do we collect about you?
Personal data: We collect basic personal data about you which does not include any special types of information or
location-based information. This includes your name, postal address and contact details such as email address and
telephone number.
By providing the Practice with your contact details, you are agreeing to the Practice using those channels to
communicate with you about your healthcare, i.e. by letter (postal address), by voice-mail or voice-message
(telephone or mobile number), by text message (mobile number) or by email (email address). If you are unhappy or
have a concern about our using any of the above channels, please let us know.
Special Category personal data: We also collect confidential data linked to your healthcare which is known as
“special category personal data”, in the form of health information, religious belief (if required in a healthcare context)
ethnicity and gender. This is obtained during the services we provide to you and through other health providers or
third parties who have provided you with treatment or care, e.g. NHS Trusts, other GP surgeries, Walk-in clinics etc.
Records which the Practice holds about you may include the following information:
- Details about you, such as your address, carer, legal representative, emergency contact details
- Any contact the Practice has had with you, such as appointments, clinic visits, emergency appointments etc.
- Notes and reports about your health
- Details about your treatment and care
- Results of investigations such as laboratory tests, x-rays etc
- Relevant information from other health professionals, relatives or those who care for you
- NHS records may be electronic, on paper, or a mixture of both.
Use of CCTV: Closed circuit television is utilised to protect the safety of our patients, staff and members of the public. To maintain privacy and dignity, CCTV is not in place where examinations or procedures are being undertaken. The Practice remains the data controller of this data and any disclosures or requests should be made to the Practice Manager.
What is the legal basis for using your data?
We are committed to protecting your privacy and will only use information collected lawfully in accordance with:
- Data Protection Act 2018
- The General Data Protection Regulations 2016
- Human Rights Act 1998
- Common Law Duty of Confidentiality
- Health and Social Care Act 2012
- NHS Codes of Confidentiality, Information Security and Records Management
How do we store your data?
We have a Data Protection regime in place to oversee the effective and secure processing of your personal and special category (sensitive, confidential) data. No third parties have access to your personal data unless the law allows them to do so and appropriate safeguards have been put in place.
In certain circumstances you may have the right to withdraw your consent to the processing of data. These circumstances will be explained in subsequent sections of this document. In some circumstances we may need to store your data after your consent has been withdrawn, in order to comply with a legislative requirement.
How do we maintain the confidentiality of your data?
Our Practice policy is to respect the privacy of our patients, their families and our staff and to maintain compliance with the General Data Protection Regulations (GDPR) and all UK specific Data Protection requirements. Our policy is to ensure all personal data related to our patients will be protected. We use a combination of working practices and technology to ensure that your information is kept confidential and secure.
Every member of staff who works for an NHS organisation has a legal obligation to keep information about you confidential. All employees and sub-contractors engaged by our Practice are asked to sign a confidentiality agreement. The Practice will, if required, sign a separate confidentiality agreement if the client deems it necessary. If a sub-contractor acts as a data processor for Sherwood House Medical Practice an appropriate contract will be established for the processing of your information.
Some of this information will be held centrally and used for statistical purposes. Where this happens, we take strict measures to ensure that individual patients cannot be identified. Sometimes your information may be requested to be used for research purposes. The Practice will always gain your consent before releasing the information for this purpose in an identifiable format. In some circumstances you can Opt-out of the Practice sharing any of your information for research purposes.
How long do we keep your data?
We are required under UK law to keep your information and data for the full retention periods as specified by the NHS Records Management Code of Practice for Health and Social Care and in accordance with National Archives
requirements.
More information on records retention can be found online at: Records Management Code of Practice – NHS
What are your data protection rights?
If we already hold your personal data, you have certain rights in relation to it.
Right to object: If we are using your data because we deem it necessary for our legitimate interests to do so, and you do not agree, you have the right to object. We will respond to your request within 30 days (although we may be allowed to extend this period in certain cases). Generally, we will only disagree with you if certain limited conditions apply
Right to withdraw consent: Where we have obtained your consent to process your personal data for certain activities (for example a research project), or consent to market to you, you may withdraw your consent at any time.
Right to erasure: In certain situations (for example, where we have processed your data unlawfully), you have the right to request us to erase your personal data. We will respond to your request within 30 days (although we may be allowed to extend this period in certain cases) and will only disagree with you if certain limited conditions apply.
Right of data portability: If you wish, you have the right to transfer your data from us to another data controller. We will help with this with a GP to GP data transfer and transfer of your hard copy notes.
National Data Opt-Out: The National Data Opt-Out is a service introduced on 25 May 2018 that allows people to opt out of their confidential patient information being used for research and planning purposes. The National Data Opt-Out replaces the previous Type 2 Opt-Out, which required NHS England not to share a patient’s confidential patient information for purposes beyond their individual care. Any patient who had a Type 2 Opt-Out has had it automatically converted to a National Data Opt-Out from 25 May 2018 and has received a letter giving them more information and a leaflet explaining the new service. If a patient wants to change their choice, they can use the new service to do this. You can find out more from the Practice or by visiting:
https://www.nhs.uk/your-nhs-data-matters
If you wish to raise a query or request relating to any of the above, please contact us. We will seek to deal with it without undue delay, and in any event in accordance with the requirements of any applicable laws. Please note that we may keep a record of your communications to help us resolve any issues which you raise.
Who do we share your data with?
We consider patient consent as being the key factor in dealing with your health information.
To provide around-the-clock safe care, we will make information available to trusted organisations for specific purposes unless you have asked us not to. We refer to these organisations to Data Processors.
To support your care and improve the sharing of relevant information to our partner organisations when they are involved in looking after you, we will share information to other systems. The general principle is that information is passed to these systems unless you request that this does not happen, but that system users should ask for your consent before viewing your record.
Our partner organisations are:
- NHS Trusts / Foundation Trusts
- GPs
- NHS Commissioning Support Units
- Independent Contractors such as dentists, opticians, pharmacists
- Private Sector Providers
- Voluntary Sector Providers
- Ambulance Trusts
- Integrated Commissioning Boards (ICBs)
- Social Care Services
- NHS England (NHSE) and NHS Digital (NHSD)
- Multi Agency Safeguarding Hub (MASH)
- Local Authorities
- Education Services
- Fire and Rescue Services
- Police and Judicial Services
- Voluntary Sector Providers
- Private Sector Providers
- DCCR Devon & Cornwall Care Record
- Other ‘data processors’ which you will be informed of
You will be informed who your data will be shared with, and in cases where your consent is required you will be asked for it. Below are some examples of when we would wish to share your information with trusted partners.
Primary Care Networks: We have formed a Primary Care Network. This means we work closely with a number of local practices and care organisations for the purpose of direct patient care. They will only be allowed to access your information if it is to support your healthcare needs. If you have any concerns about how your information may be accessed within our primary care network, we would encourage you to speak or write to us
Extended Access: We provide extended access services to our patients which means you can access medical services outside of our normal working hours. In order to provide you with this service, we have formal arrangements in place with the Clinical Commissioning Group and with other practices whereby certain key “hub” practices offer this service on our behalf for you as a patient to access outside our opening hours. Those key “hub” practices will need to have access to your medical record to be able to offer you the service. We have robust data sharing agreements and other clear arrangements in place to ensure your data is always protected and used for those purposes only.
Medicines Management: The Practice may conduct Medicines Management Reviews of medications prescribed to its patients. This service performs a review of prescribed medications to ensure patients receive the most appropriate, up-to-date and cost-effective treatments. Our local NHS Clinical Commissioning Group employs specialist pharmacists and they may at times need to access your records to support and assist us with prescribing. This reason for this is to help us manage your care and treatment.
Individual Funding Requests: An Individual Funding Request is a request made on your behalf, with your consent, by a clinician, for the funding of specialised healthcare which falls outside the range of services and treatments that CCG has agreed to commission for the local population. An Individual Funding Request is considered when a case can be set out by a patient’s clinician that there are exceptional clinical circumstances which make the patient’s case different from other patients with the same condition who are at the same stage of their disease, or when the request is for a treatment that is regarded as new or experimental and where there are no other similar patients who would benefit from this treatment. A detailed response, including the criteria considered in arriving at the decision, will be provided to the patient’s clinician.
Are there other projects where your data may be shared?
Local Research: We regularly work with local health and academic organisations to conduct research studies with the aim of improving care for the general population. We will always ask for your permission to take part, except in situations where we can demonstrate that your information has been anonymised (where you cannot be identified) and your privacy is protected. In these situations we are not required to seek consent from individuals.
Risk Stratification: Risk stratification data tools are increasingly being used in the NHS to help determine a person’s risk of suffering a condition, preventing an unplanned admission or re-admission and identifying a need for preventive intervention. Information about you is collected from a number of sources including NHS Trusts and from this GP practice. A risk score arrived at through an analysis of your de-identified information is provided back to your GP practice as data controller in an identifiable form. Risk stratification enables your GP to focus on preventing ill health and not just the treatment of sickness. If necessary, your GP may be able to offer you additional services. Please note that you have the right to opt out of your data being used in this way.
Other research projects: With your consent we would also like to use your name, contact details and email address to inform you of services that may benefit you. There may be occasions when authorised research facilities would like to invite you to participate in research, innovations, identifying trends or improving services. At any stage where we would like to use your data for anything other than the specified purposes and where there is no lawful requirement for us to share or process your data, we will ensure that you have the ability to consent or to opt out prior to any data processing taking place. This information is not shared with third parties or used for any marketing and you can unsubscribe at any time via phone, email or by informing the Practice.
When is your consent not required?
We will only ever use or pass on information about you to others involved in your care if they have a genuine need for it. We will not disclose your information to any third party without your permission unless there are exceptional circumstances. There are certain circumstances where we are required by law to disclose information, for example:
- where there is a serious risk of harm or abuse to you or other people
- where a serious crime, such as assault, is being investigated or where it could be prevented
- notification of new births
- where we encounter infectious diseases that may endanger the safety of others, such as meningitis or measles (but not HIV/AIDS)
- where a formal court order has been issued
- where there is a legal requirement, for example if you had committed a Road Traffic Offence
How can you access or change your data?
You have a right under the Data Protection legislation to request access to view or to obtain copies of the information the Practice holds about you and to have it amended should it be inaccurate. Your request should be made to the Practice and we have a form (SAR – Subject Access Request) which you will need to complete. We are required to respond to you within one calendar month.
For information from the hospital you should write direct to them. You will need to give adequate information (full
name, address, date of birth, NHS number and details of your request) so that your identity can be verified and your
records located. There is no charge to receive a copy of the information held about you
What should you do if your personal information changes?
Please contact the Practice Manager as soon as any of your details change. This is especially important for changes of address or contact details (such as your mobile phone number). The Practice will from time to time ask you to confirm that the information we currently hold is accurate and up-to-date.
Changes to our privacy policy
It is important to point out that we may amend this Privacy Notice from time to time.
Our Data Protection Officer
The Practice has appointed Umar Sabat as its Data Protection Officer. He can be contacted on the following e-mail address:
ciosicb.dpo@nhs.net
If you have any concerns about how your data is shared, or if you would like to know more about your rights in respect of the personal data we hold about you, then please contact the Practice Data Protection Officer.
How to contact the appropriate authorities
If you have any concerns about how your information is managed at your GP Practice, please contact the GP Practice Manager or the Data Protection Officer in the first instance. If you are still unhappy following a review by the GP Practice, you have a right to lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO), at the following address:
Information Commissioner
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Tel: 01625 545745
Email: https://ico.org.uk
Site search
Please DO NOT add any personally identifiable information – such as your name, NHS number, address or any other distinguishing detail – when using the site search function. The site search is intended to return information displayed on the website ONLY, and is not linked to our practice management system or your individual NHS records. Site search data is recorded in our analytics and cannot be deleted.
Violence Policy
The NHS operate a zero tolerance policy with regard to violence and abuse and the practice has the right to remove violent patients from the list with immediate effect in order to safeguard practice staff, patients and other persons. Violence in this context includes actual or threatened physical violence or verbal abuse which leads to fear for a person’s safety. In this situation we will notify the patient in writing of their removal from the list and record in the patient’s medical records the fact of the removal and the circumstances leading to it.